全部标签
目录标签

#sarif

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

27 条记录
标签为“sarif”按健康指数排序
PyPI · npm
80良好健康指数
msaad00/agent-bom
Open security scanner and self-hosted control plane for AI, MCP, and cloud. One evidence model — run scans in your environment, centralize findings, govern in your VPC.
Python · TypeScript★ 28↓ 5,301/月2026年7月16日
Apache-2.02026年7月16日 · 指标 1.13.0
PyPI
73良好健康指数
Cranot/roam-code
Local codebase intelligence CLI + MCP server for AI coding agents: SQLite code graph, 28 languages, 238 commands, 224 MCP tools, change-safety gates, audit evidence, zero API keys.
Python★ 498↓ 5,430/月2026年7月15日
Apache-2.02026年7月15日 · 指标 1.13.0
npm
72良好健康指数
microsoft/axe-sarif-converter
An axe-core reporter that outputs axe scan results in SARIF format (http://sarifweb.azurewebsites.net/)
TypeScript★ 38↓ 76.1K/月2026年7月21日
MIT2026年7月21日 · 指标 1.13.0
npm · PyPI
71良好健康指数
DNSZLSK/muad-dib
Real-time npm/PyPI supply-chain threat detection. Behavioral chain analysis, AST scanning, IOC feeds, and compound scoring engine.
JavaScript★ 15↓ 14.1K/月2026年7月14日
AGPL-3.02026年7月14日 · 指标 1.13.0
Go · PyPI
71良好健康指数
bomly-dev/bomly-cli
Free, open-source CLI for dependency intelligence, SBOMs, vulnerability auditing, and CI policy gates.
Go★ 92026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
Go
68中等健康指数
airomhq/airom
Open-source AI Bill of Materials (AIBOM) scanner: inventories AI models, datasets, prompts, embeddings, vector DBs & RAG pipelines across code, containers & Kubernetes — with file:line evidence, load-time risk detection (poisoned pickle / Keras Lambda / unsafe torch.load) and NIST AI RMF / OWASP compliance mapping. CycloneDX · SARIF · JSON.
Go · MDX★ 82026年7月23日
Apache-2.02026年7月23日 · 指标 1.13.0
PyPI
68中等健康指数
cpeoples/ansible-security-scanner
🛡️ Static security scanner (SAST) for Ansible playbooks, roles, and collections. 1,000+ rules across 30+ categories detecting malicious code, RCE, hardcoded credentials, and supply-chain risk. Outputs SARIF, CycloneDX SBOM, and GitLab SAST. SLSA Build Level 3, Sigstore-signed.
Python★ 9↓ 1,928/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
PyPI
68中等健康指数
justinchuby/lintrunner-adapters
Adapters and tools for lintrunner
Python★ 6↓ 940.1K/月2026年7月21日
自定义许可证2026年7月21日 · 指标 1.13.0
npm · crates.io
67中等健康指数
0sec-labs/foxguard
A fast universal code security scanner, written in Rust. Batteries included: supports 12 languages, TUI for triage, secrets, post-quantum audits, diff-aware scans and more 𓃥
Rust★ 277↓ 6,899/月2026年7月17日
MIT2026年7月17日 · 指标 1.13.0
PyPI
67中等健康指数
squid-protocol/gitgalaxy
Deep repository intelligence for humans and ai. Air gapped, on premise, zero dependency SAST for 50 languages regardless of compilation status. Sarif and sbom outputs.
Python★ 45↓ 0/月2026年7月14日
自定义许可证2026年7月14日 · 指标 1.13.0
Go
65中等健康指数
draugr-dev/draugr
Developer-first security scanning orchestration — describe your app in one file, run many scanners (SAST, SCA, secrets, IaC, containers, headers), get one SARIF verdict for CI & code scanning.
Go★ 02026年7月19日
Apache-2.02026年7月19日 · 指标 1.13.0
npm · PyPI
65中等健康指数
raccioly/docguard
The enforcement tool for Canonical-Driven Development (CDD). Audit, generate, and guard your project documentation. Zero dependencies.
JavaScript★ 21↓ 5,005/月2026年7月21日
MIT2026年7月21日 · 指标 1.13.0
npm · PyPI
63中等健康指数
oaslananka/boardreadyops
End-to-end hardware release pipeline for KiCad: generate, validate, sign, and package manufacturer-ready releases as a CLI and GitHub Action.
TypeScript★ 3↓ 3,738/月2026年7月17日
MIT2026年7月17日 · 指标 1.13.0
npm
61中等健康指数
goklab/guardvibe
Security infrastructure your AI can't be — deterministic, daily CVE intel past your model's training cutoff, whole-repo-aware, author-independent, and shift-left: secure_prompt secures the prompt before code generation. The security MCP for vibe coding: 450 rules, 39 tools, CLI + doctor for Next.js, Supabase, Clerk, Stripe, Prisma, Hono & MCP.
TypeScript★ 4↓ 6,125/月2026年7月17日
Apache-2.02026年7月17日 · 指标 1.13.0
Packagist · npm
60中等健康指数
blundergoat/gruff-php
Opinionated PHP code-quality analyzer that scores findings across quality pillars and emits reports for terminals, CI, SARIF, HTML, and a local dashboard.
PHP★ 1↓ 8,483/月2026年7月16日
MIT2026年7月16日 · 指标 1.13.0
Go
57中等健康指数
git-pkgs/sarif
Go library for reading, writing, and validating SARIF 2.1.0 logs
Go★ 12026年7月15日
MIT2026年7月15日 · 指标 1.13.0
PyPI · crates.io · Maven +2
56中等健康指数
mattybellx/ansede
Find authorization bugs before attackers do. Free SAST — IDOR detection, 100% CVE recall, 0% false positives. 5 languages. Fully offline.
Python · HTML★ 122026年7月17日
自定义许可证2026年7月17日 · 指标 1.13.0
Go
56中等健康指数
rudrendupaul/tenantguard
CLI security scanner for self-hosted multi-tenant AI-agent platforms. 16 fail-closed OPA/Rego rules catch tenant-isolation defects (sandbox scoping, SSRF, cross-tenant cron/auth, secret leakage). SARIF and JSON output for CI.
Go · Open Policy Agent★ 02026年7月15日
Apache-2.02026年7月15日 · 指标 1.13.0
Go
56中等健康指数
skyway-harness-builder/workflow-lint
Standalone open-source linter for Skylence .sky workflow files
Go★ 02026年7月21日
Apache-2.02026年7月21日 · 指标 1.13.0
Go
56中等健康指数
vulnetix/cli
Automate vulnerability triage which prioritizes remediation over discovery
Open Policy Agent · Go★ 25↓ 0/月2026年7月14日
自定义许可证2026年7月14日 · 指标 1.13.0
Go
55中等健康指数
kidoz/vulners-cli
CLI vulnerability scanner powered by Vulners — search, audit, scan, offline mode
Go★ 62026年7月17日
MIT2026年7月17日 · 指标 1.13.0
Go
49存在风险健康指数
bunta-expert/git-path-audit
Read-only CLI that finds Git paths that collide, change meaning, or fail to check out across Windows, macOS, and Linux.
Go★ 1↓ 0/月2026年7月14日
MIT2026年7月14日 · 指标 1.13.0
npm
48存在风险健康指数
criticaldeveloper/critical-gate
该仓库未发布描述。
TypeScript★ 1↓ 3,922/月2026年7月16日
MIT2026年7月16日 · 指标 1.13.0
Go
45存在风险健康指数
safetylab/ShadowSecurityScanner
Free, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 02026年7月21日
MIT2026年7月21日 · 指标 1.13.0
npm
43存在风险健康指数
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 19↓ 5,644/月2026年7月15日
MIT2026年7月15日 · 指标 1.13.0
Go
38存在风险健康指数
tamish560/mcprobe
Security scanner and introspection tool for MCP servers. Connect, inspect, detect injection patterns, find tool shadowing, baseline for drift. Single binary, zero dependencies, Go stdlib only.
Go★ 22026年7月20日
MIT2026年7月20日 · 指标 1.13.0
npm
35存在风险健康指数
nsasoft/nsauditor-ai-agent-skill
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows. Works with Claude Code, Cursor, Windsurf, and any MCP-aware agent.
混合★ 3↓ 4,001/月2026年7月15日
MIT2026年7月15日 · 指标 1.13.0